Package Health

lucbu/angkor-cms

The license files identify LGPL-2.1 while the manifest declares MIT, and the linked repository does not name or mention this package. A readme, tests, and a stable release provide useful structure, but they do not offset the long inactivity.

Latest v1.0.1PackagistPackagist

30%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

63

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Licensecaution

The manifest declares MIT, but the artifact contains an LGPL-2.1 license file; this mismatch creates material uncertainty about the terms consumers receive.

Lifecycle scriptscaution

Composer install, update, and project-creation scripts run during package operations. These are operationally significant and increase adoption risk, though they do not by themselves show abandonment.

Release historycaution

The package has had only two releases, both in November 2015, with no releases in the last 12 months and an age of over 10 years. This is strong evidence of abandonment.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's decade-long release gap.

Repo package mentioncaution

The repository name does not match the package name and its README does not mention the package, weakening confidence that the linked source repository actually corresponds to this release.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
laravel/framework
Version 5.1.*
—
—
laravelcollective/html
Version ~5.0
—
—
barryvdh/laravel-debugbar
Version ^2.0
—
—

Weekly Downloads

Info

Last Published
10 years ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform